Sign inSign up
AuthService

dhi.io/authservice

AuthService 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.1-alpine-fips-dev, 1.1-alpine3.24-fips-dev, 1.1.8-alpine-fips-dev, 1.1.8-alpine3.24-fips-dev

Index digest:

sha256:8e9d82a9cb467e1b3287eb28fb720e9dcdaa57c7e067f17c83f764e8ec69b747

Manifest digest:

sha256:e29a6bb680c5c7448e3d0b60d814477fcc6d4f94796603618a25d58d01e14907

Size

32.80 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/authservice:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/authservice:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/authservice@sha256:9ceb1e22337f59f74cd257b6f4225c6a3af83aed71d14c1f01672c045576bbee
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/authservice@sha256:7d01e1a8fd9117d14a202f398ccd5e4dc87b3be186f60616680c091c618ac216
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/authservice@sha256:b8d47bc1f6349c4875fe3eccd1c10bfacb77d0ea9c1381e7f23bfdac7f06c202
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/authservice@sha256:0145eee284721539f12f1188e8325c45bd142e0f2e752d1e355f4b4d0097d250
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/authservice@sha256:844fe703aaf65f1a94b6d0004a9458e11414ba1d57c48b618449ebe5205f9b0d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/authservice@sha256:c189548f0c78355c27097aed966b0d5edd0b4c6e2afc6c878e47d73c0774e496
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/authservice@sha256:2a705a74758edd0cb040e01e939011a7dab1312a9d0e09ef8fef3caa61284c4b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/authservice@sha256:bf1034afb3989f228d3e1c1b8ad108ffd04f59091d6af33aea6831551db3d843
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/authservice@sha256:f459d3982de527e695704a1519bb2e1de30577b08625d6070fbbdeca4e10c1b3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/authservice@sha256:31490f822b5a1b7570b21ea43808ee19380f93b8ad5317ad127371be867e7a95
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/authservice@sha256:4233c3cb5287b090f420fbdd661b555f6bf41304bdb97eec51c771cfe569eab6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/authservice@sha256:8f02a5807c141caac83763dd6df203a085e8f017065b246c401f5c896e599df3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/authservice@sha256:48db7ab1800dbd93a2aa29159d4328b6573454ceb186cf0d932edd3f111ddd68
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/authservice@sha256:477091409fbc09ed35352175ee031607414ba30b0732ade5ed4056e17c484288
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/authservice@sha256:b51658aab1f7d1510598c8762455ad1783f1f0ec89855e699ead8ea00d3525f1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/authservice@sha256:7aa950cdc696b9a484277f262d8cc631379b2da32700cea9b164f34ef40939fe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/authservice@sha256:386090aa69bacb623172091f2f79e3c1adf301c0208a536b71d983a7f664dbbe